Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jcgl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
61.
▲
by
jcgl
4mo ago
> This is covered by allowing for single-use credentials. IIRC the EU personal IDs will use this. Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. Each credential is only used for one req
62.
▲
by
jcgl
4mo ago
Citation needed. These numbers are quite consistent with the growth pattern that started well before usable LLMs were even a thing.
63.
▲
by
jcgl
4mo ago
First of all, multi-party democracy needn’t be slow. Parliamentary systems in multi-party countries often react faster than the US. This is due in part to legislation being systematically easier to pass. Second of all, winner-take-all presi
64.
▲
by
jcgl
4mo ago
How do you reconcile that position with what Graphene OS lists as requirements for support, as linked by another commenter? https://grapheneos.org/faq#future-devices I’m not an expert, but all the listed points there sound
65.
▲
by
jcgl
4mo ago
I’m no expert, but as long as they’re represented by tokens in the end, they’re just tokens. Even if you train the transformer to treat them specially, a token is a token, and there’s no free lunch. At best, you’re going to be trading off b
66.
▲
by
jcgl
4mo ago
Case-in-point: just started a new chat with a new person (we had a previous room in common)--My desktop client, NeoChat, shows "This message is encrypted and the sender has not shared the key with this device." for all of their
67.
▲
by
jcgl
4mo ago
> has good clients So far, I've only found clients with different bugs. Calling them good would be a stretch. Passable, perhaps. But the scene as a whole is more of a choose-the-bugs-to-live-with situation than choose-a-good-clien
68.
▲
by
jcgl
4mo ago
You’re mistaken: DKIM always signs the entire From field. Signing is done on the MTA, so yes, it is “the reputation of the server” like you say, but “server” can be a relatively granular thing here, using different DKIM selectors for differ
69.
▲
by
jcgl
4mo ago
This is mostly what it is for me too. We're all awash in an information deluge, and we need heuristics to keep from drowning. Human effort, proof-of-work if you will, is a heuristic that helps with the AI-generated part of the deluge.
70.
▲
by
jcgl
4mo ago
That's not something that is known how to do in a reliable fashion, right? It sounds quite like the problem where transformers are unable to be updated/taught over time.
71.
▲
by
jcgl
4mo ago
That may very well be the case. In fact, I'm nearly certain that you're right. But it doesn't change the fact that open weight models are altogether insufficient on a number of important dimensions regarding freedom and trans
72.
▲
by
jcgl
4mo ago
I don’t see how that helps, unless you actually mean open source, rather than open weights like most people do. Without everything that goes into the model, including training data, these things are opaque.
73.
▲
by
jcgl
4mo ago
No, because in a context where you'd have a port number, the address is surrounded with brackets: [2001:db8::]:80
74.
▲
by
jcgl
4mo ago
Beyond the :: stuff, I can only think of IPv4-mapped IPv6 addresses, where you can represent a trailing 32 bits as dotted decimal (e.g. 2001:db8::192.0.2.1). And the :: stuff also exists in IPv4 in the same way, just using dots instead of c
75.
▲
by
jcgl
4mo ago
Outside of interface identifiers, what is so complex about them? I think they end up being purely simpler than IPv4 addresses since they can’t be mistaken for DNS names.
76.
▲
by
jcgl
5mo ago
How do you make sure you’re getting enough iodine?
77.
▲
by
jcgl
5mo ago
> Zero days for chrome will cost more than zero days for Firefox because Chrome takes security more seriously They may cost more for Chrome, but it needn’t be because Chrome takes security more seriously; Chrome’s greater market share al
78.
▲
by
jcgl
5mo ago
Damn, good call. Really reinforces the need for sandboxing. Still doesn’t negate the value of OpenSwitch, since the majority of malware won’t do that. But really good to keep in mind.
79.
▲
by
jcgl
5mo ago
Excellent example, thank you. This is the kind of stuff that skeeves me out and is entirely within the model of threats that I want to guard against. Sandboxing + OpenSnitch is good stuff. And, ofc, npm bad.
80.
▲
by
jcgl
5mo ago
> Personally I don't allow outbound connections from almost any app, except web browsers to port 80/443. So nodejs, pip, ruby, curl, wget, etc, opening unexpected outbound connections is a big red flag for me. Yep, exactly. Rej
81.
▲
by
jcgl
5mo ago
> That wouldn't help in that case as exfiltrated data is committed to public GitHub repositories Correct in general that it doesn't protect against stuff like that. But this whitelisting is done per-command (in this case, the w
82.
▲
by
jcgl
5mo ago
On my personal machine, I run OpenSnitch. Much better defense against data exfil if you reject outbound connections to unexpected/unwanted hosts.
83.
▲
by
jcgl
5mo ago
I originally bought the touchpad for my UHK. But, much to my surprise, I have gravitated towards the keyboard's built-in mouse layer over time! Now I scarcely plug in the touchpad (or even key cluster) modules at all. As a sidenote, I
84.
▲
by
jcgl
5mo ago
Forgot to mention: you can use systemd-socket-proxyd to bridge to an application that doesn't support socket activation too: https://www.man7.org/linux/man-pages/man8/systemd-socket-pro...
85.
▲
by
jcgl
5mo ago
Yes, I agree that device-bound credentials (DBC?) are a really big deal here. Just wanted to get the story straight. When it comes to the notion of requiring DBCs without also requiring remote attestation, how do you deal with solving the
86.
▲
by
jcgl
5mo ago
> For all they know you’re just some gullible user that clicks through every fishing email you get. Passkeys are non-phishable. That's part of their schtick. I'm not a huge passkey fan myself, but this is a real benefit.
87.
▲
by
jcgl
5mo ago
Point taken about the core team being stretched thin. But I don't see how the "increase stability of some core crates" is enough to change the packaging practices/culture. Maybe I'm wrong, but you really don't
88.
▲
by
jcgl
5mo ago
One man's bloat is another man's batteries-included, I guess? My argument would be that if a more featureful standard library could get Rust closer to the superior dependency culture of Go, it'd be worth it. As-is, Rust depen
89.
▲
by
jcgl
5mo ago
> Even for sites that don't offer granular feeds, every major feed reader offers filtering options, a lot of them offer fairly complex regex filtering. This is true to some degree, but regex filtering or really any strictly logical
90.
▲
by
jcgl
5mo ago
If the application supports it, there’s also systemd socket activation (or traditional inetd sorta stuff too if that fits)
More ›